Calibrating on AI, Risk, and Next Steps
9-9-2026 (Wednesday)
Hello, and welcome to The Intentional Brief - your weekly video update on the one big thing in cybersecurity for middle market companies, their investors, and executive teams.
I’m your host, Shay Colson, Managing Partner at Intentional Cybersecurity, and you can find us online at intentionalcyber.com.
Today is Wednesday, September 9, 2026, and we’re digging out of the long Labor Day weekend with this episode coming out a day late. Hopefully everyone had a restful and productive weekend, and a reminder that the Strait of Hormuz is still closed.
Calibrating on AI, Risk, and Next Steps
It’s not gone unnoticed that most of our episodes lately are more about AI than cybersecurity, but I’d offer that they’re actually still really about the same thing. In fact, the vast majority of conversations with our clients that used to be about security questions are now about AI.
And it’s understandable - last week we saw a torrent of new models announced by all the major players, led by OpenAI’s new GPT-6 Astra launch. They’re framing this as “a generational leap in capability” and leaders across organizations are continuing to wrestle with what this means for them.
As we’ve covered here, I think generally what we’ll see is an acceleration around finding and exploiting the weaknesses that are already present in our environments - whether those are technical systems or humans.
In addition to launching a new model, OpenAI’s expanding their “Daybreak” program, framing it as helping blue teams as “defenders have a narrowing window to prepare” to defend against AI-enabled cyber attacks.
This framing is echoed in Greg Brockman’s personal blog post, The Defender’s Window. If you don’t know his name yet, he’s the President of OpenAI, so it should be no surprise that these messages are tightly aligned.
That said, there are some interesting nuggets in the piece and I’d suggest you give it a read. In particular, the core of his thesis is that you’ve got to use AI to defend against AI (which, I think is only partially true). His best advice, however, is his last item, which is “iterate rapidly.”
More than anything, the rate of change of these capabilities is going to force organizations to move at a new - and extremely uncomfortable - pace. This will also generate some unintended consequences, as we’ve covered extensively here, but those looking to take advantage or defend against this technology won’t have a choice. Ignoring or avoiding seems less and less possible, given the prevalence of the technology or fact that it’s going to find its way into your organization whether you sanction it or not.
Implied in Brockman’s piece is that this open window for defenders will eventually close. He’s not explicit about it, but I think it’s also worth thinking through more deeply what these implications are. What happens when the window closes? Is the HuggingFace event a preview of this? What does this window “closing” mean for you and your organization? Is it signified as closed when you suffer an AI-driven attack? Or before then?
Again, these mental models can be useful tools, but - to crib a bit from the Amazon leadership principles - maintain your Bias Towards Action and don’t be afraid to Have Backbone; Disagree and Commit. Leadership in this time is going to present some unique challenges, but - at least for now - we’re all in it together.
Fundraising
Fundraising numbers are up again this week, with more than $23B in newly committed capital, led by two large raises:
CVC Capital Partners raised $10b for its sixth PE secondaries fund; and
A16z expanded its fifth growth fund to $8.5b.
We’re still waiting for the IPOs of both OpenAI and Anthropic, and we’re seeing some big movements in the chip space, with Nvidia acquiring HuggingFace for $13B and Qualcomm giving Amazon $4B in stock warrants as part of a $60B chip purchase agreement.
Wild times with numbers this big.
A reminder that you can find links to all the articles we covered below, find back issues of these videos and the written transcripts at intentionalcyber.com.
We’ll see you next week for another edition of the Intentional Brief.
Links
https://www.thedeepview.com/articles/openai-s-astra-leans-into-agentic-tasks-and-safety
https://hormuzstraitmonitor.com
https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/
https://www.amazon.jobs/content/en/our-workplace/leadership-principles
https://blogs.nvidia.com/blog/nvidia-to-acquire-hugging-face/